Did Chinese AI companies secretly tap US models to close the technology gap? That is the central question hanging over China’s tech sector following a wave of allegations from Washington and American AI lab Anthropic. According to a joint advisory by the National Security Agency, FBI, and Cybersecurity and Infrastructure Security Agency last month, Chinese AI developers have been systematically extracting capabilities from US frontier models to reduce their own computing, electricity and research costs. US Treasury Secretary Scott Bessent similarly warned in July that Chinese firms were engaged in large-scale “distillation”. Specifically, Anthropic claimed Chinese AI developers used fraudulent accounts and proxy networks to siphon reasoning data from its flagship model, Claude – and in some cases even used the US model as a covert back end for their own apps. Here’s a closer look at whether the accusations hold water – and why Beijing is taking those claims seriously. What are Anthropic’s allegations? Anthropic accused Chinese developers of conducting “industrial-scale” distillation, a technique in which outputs from a more capable “teacher” model are used to improve another model. While model distillation is a common practice across the AI industry, Anthropic claimed Chinese firms crossed ethical lines. According to a report published by the company last month, Chinese labs circumvented usage restrictions through fraudulent accounts and third-party proxy services to harvest Claude’s output and reasoning traces at scale. Anthropic reported that over just 10 days, Moonshot routed almost 300,000 user requests, primarily to the Opus model. The Chinese company utilised a proxy network of 5,380 fraudulent accounts largely based in Singapore and Japan, Anthropic claimed. Furthermore, Anthropic alleged that some companies used Claude as a hidden back end. This meant users believed they were interacting with a domestic Chinese model when their queries were actually being processed by the US firm’s servers, the firm said. Moonshot did not respond to a request for comment. How strong is the evidence? Industry analysts are divided over the credibility and attribution of Anthropic’s findings. Konstantin Pilz, co-founder and fellow at the Washington-based Centre for Technology and Statecraft, considered the claims credible, noting that they reflected the intense pressure on Chinese developers facing US chip export restrictions. “To not fall further behind on AI model performance, Chinese AI companies have to use adversarial distillation on a large scale,” Pilz said, suggesting that distillation allowed domestic developers to leapfrog expensive reasoning data generation. Ben Hayum, a research assistant at the Centre for a New American Security (CNAS), said Anthropic had long been able to gather threat-intelligence signals that could detect and attribute distillation attacks. However, other experts argued that pinpointing direct blame on Chinese AI companies was not always straightforward. Kyle Chan, a fellow at the Brookings Institution, noted that third-party proxy services – or “transfer stations” – might be the real culprits. These proxies might secretly divert user requests to Claude to obtain and sell reasoning data without the direct involvement of the Chinese AI labs, he said. Wang Zebin, an investment manager at Shenzhen-based private equity firm JG Investment focused on large language models and embodied intelligence, said Anthropic’s report “does not provide enough concrete examples to independently verify how those companies obtained or used the model outputs”, adding that the specific distillation methods described in the report were questionable. Why might Beijing be concerned? Chinese regulators were reportedly investigating domestic AI labs following Anthropic’s report. According to a report by The Information last month, the Cyberspace Administration of China questioned seven developers named by Anthropic before narrowing its focus to DeepSeek and Moonshot. DeepSeek did not respond to a request for comment. If the report was true, the main concern for Beijing would not be intellectual property theft or model copying, but data security, according to Pilz. Anthropic claimed that some of the prompts sent to Claude contained sensitive information from state-affiliated organisations and companies, as well as names, email addresses, and other corporate data. Re-routing sensitive data to American AI model providers may pose a “very significant security issue for China”, Chan said, adding that it would be “even more severe” than exposing search histories because users share so much data with AI. Coding requests in particular can leak underlying IT infrastructure or login credentials. “China should be seriously questioning this,” Hayum said, noting that regulators must evaluate whether they can trust domestic tech firms to safeguard sensitive data and manage emerging cybersecurity risks. Even if the allegations were true, however, Chan expected Beijing to handle the matter discreetly to avoid publicly validating Anthropic’s claims. Additional reporting by Minxiao Chang